First published: Wed Feb 19 2020(Updated: )
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to `NovaProxyRequestHandlerBase.new_websocket_client` in `console/websocketproxy.py`.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Nova | >=20.0.0<20.1.0 | 20.1.0 |
pip/Nova | >=19.0.0<19.1.0 | 19.1.0 |
pip/Nova | <18.2.4 | 18.2.4 |
OpenStack Nova-LXD | <18.2.4 | |
OpenStack Nova-LXD | >=19.0.0<19.1.0 | |
OpenStack Nova-LXD | >=20.0.0<20.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-9543 is low with a severity value of 3.3.
CVE-2015-9543 affects OpenStack Nova versions before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0.
The vulnerability in CVE-2015-9543 is the leakage of consoleauth tokens into log files, which can be exploited by an attacker with read access to obtain tokens used for console access.
All Nova setups using novncproxy are affected by CVE-2015-9543.
To fix CVE-2015-9543, upgrade to OpenStack Nova version 18.2.4 or later, 19.1.0 or later, or 20.1.0 or later.